PyPI: flask-appbuilder
CVE-2024-45314
Safety vulnerability ID: SFTY-20240904-35920
Safety legacy ID: pyup.io-73129
In flask-appbuilder affected versions, the authentication database login form's default cache directives allow browsers to locally store sensitive data. This poses a security risk, particularly in environments where computer resources are shared. The latest release contains a patch addressing this issue. If upgrading is not feasible, users can mitigate the vulnerability by configuring their web server to send specific HTTP headers for the /login endpoint, following the instructions provided in the GitHub Security Advisory.
Overview
Flask-AppBuilder's login form allows browser to cache sensitive fields
Advisory
In flask-appbuilder affected versions, the authentication database login form's default cache directives allow browsers to locally store sensitive data. This poses a security risk, particularly in environments where computer resources are shared. The latest release contains a patch addressing this issue. If upgrading is not feasible, users can mitigate the vulnerability by configuring their web server to send specific HTTP headers for the /login endpoint, following the instructions provided in the GitHub Security Advisory.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20240904-35920/CVE-2024-45314
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45314
- https://github.com/advisories/GHSA-fw5r-6m3x-rh7p
- https://github.com/dpgaspar/Flask-AppBuilder/commit/3030e881d2e44f4021764e18e489fe940a9b3636
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-fw5r-6m3x-rh7p
- https://github.com/dpgaspar/Flask-AppBuilder/commit/3030e881d2e44f4021764e18e489fe940a9b3636
- https://nvd.nist.gov/vuln/detail/CVE-2024-45314
- https://github.com/advisories/GHSA-fw5r-6m3x-rh7p
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
